Canopy Settings
In Canopy Settings you configure your organization: company details and branding, data residency, sign-in and MFA methods, SSO and provisioning, and API keys.
Overview
Section titled “Overview”Settings is where you configure your own organization in Canopy. It opens at /settings and presents your organization’s configuration as five cards, in this order:
| Card | What it holds |
|---|---|
| Organization | Company details and light and dark branding |
| Vendor handle | Your organization’s namespace for hosted connectors |
| Inference data residency | The country-lock for AI inference |
| Authentication | Sign-in and MFA, SSO and auto-provisioning, and SSO access, all in one card |
| API keys | Who may create API keys, and revocation |
Each card saves independently. There is no page-level Save.
Settings is organization-level configuration. It is distinct from the personal Profile menu in the top-right corner, which holds your own account details. See Profile vs Settings below.
Organization
Section titled “Organization”The Organization card holds your company details and branding, including separate light and dark logo uploads so your brand looks right in both themes.
To update your branding:
- Open Settings and find the Organization card.
- Edit your organization’s name and company details.
- Upload a light logo and a dark logo. Two uploads let Canopy show the right logo against light and dark backgrounds.
- Save the card to apply the changes across your organization.
Vendor handle
Section titled “Vendor handle”Your vendor handle is your organization’s namespace. The card describes it as being prefixed onto every hosted connector you publish, in the form <handle>/<connector>, including the URLs you hand to your own MCP clients.
- Format: 2 to 39 characters, lowercase letters, numbers, and single hyphens. It cannot be all numbers.
- Save: enter the handle and select Save handle. Canopy confirms with “Handle updated.”
A rename can be refused, and Canopy names the reason rather than just failing:
| Rejection | What it means |
|---|---|
| Not valid | The handle breaks the format rule above. |
| Already in use | Another organization currently holds it. Pick a different one. |
| Previously freed | A handle released by an earlier rename can never be reclaimed, by anyone. Pick a different one. |
| Cooldown | You renamed within the last 5 minutes. Wait for the cooldown to pass and try again. |
If you are in demo mode, this card is hidden and locked: the value shows as bullets and the field reads “Hidden and locked while PII-safe mode is on.”
Inference data residency
Section titled “Inference data residency”The Inference data residency card holds a single control, Country-lock LLM inference. When it is on, only in-country model bindings are used for your organization; cross-border (global) models are hidden and cannot be selected or called.
Turning it on saves directly. Turning it off is treated as removing a compliance control:
- An inline warning appears as soon as you uncheck it, before you save.
- Saving opens a confirmation dialog, Disable country-lock?, which spells out that requests may be routed to global or cross-border providers and that previously hidden models become available.
- The change is audited.
If Canopy cannot read the current setting, it disables the control and says so: “Couldn’t load the current data-residency setting. Refresh before changing it.” Reload before you change anything, so a save cannot clear a lock you could not see.
Use this when your data must stay within its country. The same control is also available per customer on the customer’s Detail tab. See Adding a New Customer.
Sign-in & MFA
Section titled “Sign-in & MFA”The Sign-in & MFA section of the Authentication card controls how members of your organization authenticate. Here you choose which second-factor (MFA) methods your users are allowed to use when they sign in.
This is the organization-level counterpart to the per-user setup your members do themselves. Once you decide which methods are allowed here, each user enrolls their own second factor. See Setting Up Multi-Factor Authentication for the end-user steps in ThreoAI.
Allowed methods, migration, and cascade
Section titled “Allowed methods, migration, and cascade”Unchecking an MFA method stops new enrollments in it; users already enrolled keep working until you migrate them. Two controls apply when you save:
- On save, also - Migrate users off methods I just disabled: a one-time action that switches affected users to the first allowed method and emails them. It runs once, then resets.
- Cascade to child organizations: how the change propagates to child tenants.
- Don’t change child organizations (default) - children keep their own MFA configuration.
- Tighten - also remove your disabled methods from children, so stricter children stay stricter.
- Overwrite - force children to your exact list, wiping their existing configuration.
The safe default is Don’t change child organizations. Tighten and Overwrite reach into child tenants, so use them deliberately.
You cannot save with every method unchecked. Canopy rejects it with “At least one MFA method must be enabled.” Selecting Migrate users off methods I just disabled asks you to confirm first; the dialog states that affected users are switched to the first allowed method, emailed about the change, and that this may briefly disrupt their next sign-in.
SSO and Auto-Provisioning
Section titled “SSO and Auto-Provisioning”Inside the Authentication card, SSO & auto-provisioning registers your SSO organization identifiers so matching users are provisioned automatically, and lets you enforce SSO sign-in. SSO access, directly below it, manages the resulting provisioned-user list and the deny list.
For the full walkthrough - provisioning rules, the Add rule dialog, enforcement, and the access lists - see SSO and Auto-Provisioning.
API Keys
Section titled “API Keys”The API keys card controls who in your organization may create API keys in Threo, and lets you revoke any active key. Enablement is opt-in and off by default. See API Keys for details.
Profile vs Settings
Section titled “Profile vs Settings”Settings is organization-level: branding, company details, and the sign-in rules that apply to everyone in your organization. The Profile menu in the top-right corner is personal: your own account details and preferences. Change your organization’s configuration in Settings; change your own account from Profile.
Frequently Asked Questions
Section titled “Frequently Asked Questions”Where do I change my own profile? Open the Profile menu in the top-right corner. Settings is for organization-level configuration; Profile is for your personal account details and preferences.
What logo sizes and formats should I use? Upload a light logo and a dark logo so branding renders correctly in both themes. Use clear, appropriately sized image files for each; confirm the exact supported formats and dimensions in the upload control before you save.
Who can change the sign-in methods? The allowed sign-in and MFA methods are an organization-level setting, so they are changed by administrators in Settings, not by individual users.
Related
Section titled “Related”- Canopy Overview - the admin portal at a glance
- Managing User Permissions - roles and app permissions per user
- Setting Up Multi-Factor Authentication - the end-user MFA setup in ThreoAI
- Platform Admin - models, MCP, and skills for your organization

